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Amendments to the Claims: 

This listing of claims will replace all prior versions, and listings, of claims in the application: 
Listine of Claims: 

1 . (Currently Amended) A secure parameter generating device in an algebraic 
curve crypto graph v having the definition expression of ceY^ + 6X^ +1 0 , comprising: 

an input means for receiving two different prime numbers (a, b) specifying degree of 
complexity of a curve and size (n) of an encryption key to be used; 

a Stickelberger element computing device for computing a Stickelberger element (co) 
in an ab cyclotomic, based on the prime number (a) and the prime nimiber (b); 

a Jacobian addition candidate value computing device for computing Jacobian 
addition candidate value j corresponding to the two different prime numbers a and b, and a 
prime number p corresponding to the Jacobian addition candidate value j, based on the prime 
number (a), the prime number (b), the size (n) of an encryption key, and the Stickelberger 
element (co);. 

an order candidate value computing device for computing a class H consisting of a 
plurahty of candidate values for order of a Jacobian group of an algebraic curve specified by 
the prime number a and the prime number b, based on the prime number a, the prime number 
b, and the Jacobian addition candidate value j; 

a security judging device for searching for a candidate value h meeting a security 
condition such as almost prime number characteristic from the class H, according to the class 
H; 

a parameter deciding device for computing a parameter of an algebraic curve whose 
order of the Jacobian group is in accord with the candidate value h, of the algebraic curves 
specified by the prime number a, the prime number b, and the prime number p, based on the 
prime number a, the prime number b, the prime number p, and the candidate value h; and 
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an output device for supplying the parameter of the algebraic curve computed by said 
parameter deciding device. 

2. (Currently Amended) A secure parameter generating device in an algebraic curve 
crvptograph v having the definition expression of aY^ + 6X^ +1=0 as claimed in Claim 1, 
further comprising: 

an a-storing means, a b-storing means, and an n-storing means for respectively storing 
the prime number a, the prime number b, and the size n of the encryption key received by said 
input means; 

a co-storing means for storing a Stickelberger element co computed by said 
Stickelberger element computing device; 

a p-storing means and a i-storing means for respectively storing the prime number p 
and the Jacobian addition candidate value j computed by said Jacobian addition candidate 
value computing device; 

an H-storing means for storing the class H computed by said order candidate value 
computing device; and 

an h-storing means for storing the candidate value h found by said security judging 

device. 

3. (Currently Amended) A secure parameter generating device in an algebraic 
curve rryptngr^iph v having the definition expression of aY^ + gx' +1 = 0 as claimed in Claim 
1, further comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
CO by use of the equation co = St [<t/a> + <t^>] 6 _{-t-* } (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, X indicates the maximum integer not 
exceeding a rational number X, <X> indicates a fi-actional portion X-[X] of the rational number 
X, 6t indicates Galois mapping C -> C in the ab cyclotomic (C, is the primitive ab root of 1)), 
based on the prime number a and the prime number b. 
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4. (Currently Amended) A secure parameter generating device in an 
algebraic curve cryptograph y having the definition expression of aY^ + 8X^ +1 
= 0-as claimed in Claim 1, further comprising: 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 
2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j == y®. 

5. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph y having the definition expression of aV' + 8X^ +1=0 as claimed in Claim 
1, further comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
CO by use of the equation co = Zt [<t/a> + <t/b>] 6 _{-t'^} (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, [X,] indicates the maximum integer not 
exceeding a rational number X, <X> indicates a fractional portion X-[X] of the rational number 
X, 6t indicates Galois mapping ^ ^ in the ab cyclotomic (i; is the primitive ab root of 1)), 
based on the prime number a and the prime number b; and 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer y generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 
2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element (o, and computing the Jacobian addition 
candidate value j by use of the equation j = y'^. 

6. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph y having the definition expression of q;Y^ + 8 X^ 4-1=0 as claimed in Claim 
1, further comprising: 
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said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormKjQ (1+ (-Q*" j) (where Nonn_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when ^ is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,..- ,h2ab}- 

7. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph v having the definition expression of aY'^ + QX^ +1 = 0 as claimed in Claim 
1, further comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
CO by use of the equation co = Zt [<t/a> + <t/b>] 6 _{-t"^} (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, [k] indicates the maximum integer not 
exceeding a rational number X, <X> indicates a fractional portion X'[X] of the rational number 
X, 6t indicates Galois mapping ^ ^Mn the ab cyclotomic (i; is the primitive ab root of 1)), 
based on the prime number a and the prime nimiber b; and 

said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = Norniiqg (1+ (-Cfj) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, H=={hi,h2,... ,h2ab} 

8. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph v having the definition expression of aY^ + 3X^' +1 ^ 0 as claimed in Claim 
1, further comprising: 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer y generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 
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2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y'"; and 

said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hu = NormRiQ (l+i-Cfj) (where Norm_{K|Q} is a norm mapping in the 
ab cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when C, is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, H={hi,h2,... ,h2ab} 

9. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph v having the definition expression of aY" + BX^ +1=0 as claimed in Claim 
1 , fiulher comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
CO by use of the equation co = St [<t/a> + <t/b>] 6 _{-f '} (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, [X] indicates the maximum integer not 
exceeding a rational number X, <l> indicates a fractional portion of the rational number 
X, 6, indicates Galois mapping C -> C in the ab cyclotomic (^ is the primitive ab root of 1)), 
based on the prime number a and the prime number b; 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer y generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 
2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y"; and 

said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormKiQ (1+ i<f j) (where Norm_{K|Q} is a norm mapping in the ab 
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cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when ^ is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}. 

10. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph v having the definition expression of aY^ + QX^ +1=0 as claimed in Claim 
1, further comprising: 

said parameter deciding device for requiring the primitive a root and the primitive b 
root (^b of 1 with the prime number p used as the divisor, based on the prime number a, the 
prime number b, the prime number p, and the candidate value h, generating a random point G 
over an algebraic curve defined by the equation C,^^ + <;b"' + 1 = 0, as for each integer 1 
from 1 to a inclusively and each integer m from 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, C,J, and C,^"^ as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
number b if the result is equal to an identity element in the Jacobian group. 

1 1 . (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph v having the definition expression of aY^ + 3X^' +1 ^ 0 as claimed in Claim 
1, further comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
(o by use of the equation co = St [<t/a> + <t^>] 6 _{-f^ } (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, [X] indicates the maximum integer not 
exceeding a rational number X, <X> indicates a fractional portion X- [X] of the rational 
number X, 6t indicates Galois mapping -><;Mn the ab cyclotomic (^ is the primitive ab root 
of 1)), based on the prime number a and the prime number b; and 

said parameter deciding device for requiring the primitive a root C,^^ and the primitive b 
root ^b of 1 with the prime number p used as the divisor, based on the prime number a, the 
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prime nvimber b, the prime nvmiber p, and the candidate value h, generating a random point G 
over an algebraic curve defined by the equation ^a', + ^b"" X*" + 1=0, as for each integer 1 
from 1 to a inclusively and each integer in fi-om 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, ^a", and as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
number b if the result is equal to an identity element in the Jacobian group. 

12. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptography having the definition expression of a Y" + BX^ +1 = 0 as claimed in Claim 
1, further comprising: 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer y generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 
2ny(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y"; and 

said parameter deciding device for requiring the primitive a root t^^ and the primitive b 
root Cb of 1 with the prime number p used as the divisor, based on the prime number a, the 
prime number b, the prime number p, and the candidate value h, generating a random point G 
over an algebraic curve defined by the equation ^a', Y^ + ^b"" X" + 1=0, as for each integer 1 
fi-om 1 to a inclusively and each integer m from 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, and {^b"" as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
mmiber b if the result is equal to an identity element in the Jacobian group. 

13. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptography having the definition exoressi nn of ofV + flX'' +1 = 0 as claimed in Claim 
1, fiirther comprising: 
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said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = Normic/g (1+ (-Q^ j) (where Norm_{K|Q}, is a norm mapping in the 
ab cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}; and 

said parameter deciding device for requiring the primitive a root C,^ and the primitive b 
root d;b of 1 with the prime number p used as the divisor, based on the prime number a, the 
prime number b, the prime number p, and the candidate value h, generating a random point G 
over an algebraic curve defined by the equation + C,^"^ + 1=0, as for each integer 1 

from 1 to a inclusively and each integer in from 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, C,^\ and Qj^ as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
number b if the result is equal to an identity element in the Jacobian group. 

14. (Currently Amended) A secure parameter generating device in an algebraic 
curve rryptngTRph v having the definition express ion of q:Y^ + QX^ +1-0 as claimed in Claim 
1 , fiirther comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
CO by use of the equation co = Zt [<t/a> + <t^>] 6 _{-f*} (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, [X] indicates the maximum integer not 
exceeding a rational number X, <X> indicates a fractional portion of the rational number 
X, 6t indicates Galois mapping C -> C in the ab cyclotomic (d; is the primitive ab root of 1)), 
based on the prime number a and the prime number b; 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer y generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 

-9- 



015.652399.1 



Atty. Dkt. No. 040405-0326 



2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y^; and 

said parameter deciding device for requiring the primitive a root and the primitive b 
root i^b of 1 with the prime number p used as the divisor, based on the prime number a, the 
prime number b, the prime number p, and the candidate value h, generating a random point G 
over an algebraic curve defined by the equation Ca\ + i;b"' X*" + 1=0, as for each integer 1 
from 1 to a inclusively and each integer in from 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, C,^\ and Q^T as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
number b if the result is equal to an identity element in the Jacobian group. 

15. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptography having the definition expression of aY^ + gX^ -f 1 0 as claimed in Claim 
1, further comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
CO by use of the equation (o = St [<t/a> + <\Jh>'\ 6 _{-t"^} (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, [X\ indicates the maximum integer not 
exceeding a rational number X, <X> indicates a fi-actional portion X'[X] f the rational number 
X, 6t indicates Galois mapping C -> C in the ab cyclotomic (d; is the primitive ab root of 1)), 
based on the prime number a and the prime number b; 

said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = Normjc/q (1+ (-Q^ j) (where Nomi_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer firom 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}; and 
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said parameter deciding device for requiring the primitive a root (I^a and the primitive b 
root of 1 with the prime number p used as the divisor, based on the prime number a, the 
prime number b, the prime number p, and the candidate value h, generating a random point G 
over an algebraic curve defined by the equation C,^\ + (^b"" + 1=0, as for each integer 1 
from 1 to a inclusively and each integer in from 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, C^^^ , and C^^T as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
nimiber b if the result is equal to an identity element in the Jacobian group. 

16. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptograph v having the definition expression of aY^ + j3X^' +1=0 as claimed in Claim 
1, further comprising: 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer y generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 
2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y"^; 

said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormK/Q (1+ {<f ]) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,." ,h2ab}; and 

said parameter deciding device for requiring the primitive a root (^a and the primitive b 
root of 1 with the prime number p used as the divisor, based on the prime number a, the 
prime number b, the prime number p, and the candidate value h, generating a random point G 
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over an algebraic curve defined by the equation C,a\ + CjJ^ x'' + 1-0, as for each integer 1 
from 1 to a inclusively and each integer m from 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, C,^, and (^b*" as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
number b if the result is equal to an identity element in the Jacobian group. 

17. (Currently Amended) A secure parameter generating device in an algebraic 
curve cryptography having the definition expression of oiY^ + gX*' +1 = 0 as claimed in Claim 
1, fiirther comprising: 

said Stickelberger element computing device for computing the Stickelberger element 
CO by use of the equation co = Zt [<t/a> + <t/b>] 6 _{-t'' } (where, t runs on a typical series of 
irreducible residue class with ab used as a divisor, [X,] indicates the maximum integer not 
exceeding a rational number X, <X> indicates a fractional portion X-[k] of the rational number 
X, 6, indicates Galois mapping C in the ab cyclotomic (^ is the primitive ab root of 1)), 
based on the prime nimiber a and the prime nimiber b; 

said Jacobian addition candidate value computing device for generating a at random, 
which is an algebraic integer y generating a prime ideal of a cyclotomic K generated by the 
primitive ab root of 1 and whose absolute norm becomes the prime number p of bit length 
2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element o, and computing the Jacobian addition 
candidate value j by use of the equation j = y"; 

said order candidate value computing device for computing a candidate value hk for 
the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormK/g (1+ i<f }) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}; and 
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said parameter deciding device for requiring the primitive a root (I^a and the primitive b 
root C,\i of 1 with the prime number p used as the divisor, based on the prime number a, the 
prime number b, the prime number p, and the candidate value h, generating a random point G 
over an algebraic curve defined by the equation C^^, + C,^"^ + 1=0, as for each integer 1 
from 1 to a inclusively and each integer m from 1 to b inclusively, computing the h-fold of an 
element in the Jacobian group indicated by the point G, and supplying p, C,^ , and CjJ^ as the 
parameter of an algebraic curve whose order of the Jacobian group is in accord with the 
candidate value h, of the algebraic curves specified by the prime number a and the prime 
number b if the result is equal to an identity element in the Jacobian group. 

18. (Currently Amended) A secure parameter generating method in an algebraic 
curve crvptographv having the definition expression of ofY^ + gX^' +1 0 , comprising the 
steps of: 

a Stickelberger element computing procedure for computing a Stickelberger element 
CO in an ab cyclotomic, respectively based on two different prime numbers a and b specifying 
degree of complexity of curve; 

a Jacobian addition candidate value computing procedure for computing Jacobian 
addition candidate value j corresponding to the two different prime numbers a and b, and a 
prime number p corresponding to the Jacobian addition candidate value j, respectively based 
on the prime number a, the prime number b, the size n of an encryption key, and the 
Stickelberger element co; 

an order candidate value computing procedure for computing a class H consisting of a 
plurality of candidate values for order of a Jacobian group of an algebraic curve specified by 
the prime number a and the prime number b, respectively based on the prime number a, the 
prime number b, and the Jacobian addition candidate value j; 

a security judging procedure for searching for a candidate value h meeting a security 
condition such as almost prime number characteristic from the class H, according to the class 
H; and 
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a parameter deciding procedure for computing a parameter of an algebraic curve 
whose order of the Jacobian group is in accord with the candidate value h, of the algebraic 
curves specified by the prime number a, the prime number b, and the prime number p, 
respectively based on the prime number a, the prime number b the prime number p, and the 
candidate value h. 

19, (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of oY'' + j3X^ +1 0 as claimed in Claim 
18, further comprising: 

a procedure for storing a Stickelberger element co computed by said Stickelberger 
element computing procedure into said (o-storing means; 

a procedure for respectively storing the prime number p and the Jacobian addition 
candidate value j computed by said Jacobian addition candidate value computing procedure 
into said p-storing means and j -storing means; 

a procedure for storing the class H computed by said order candidate value computing 
procedure into said H-storing means; and 

a procedure for storing the candidate value h found by said security judging procedure 
into said h- storing means. 

20. (Currently Amended) A secure parameter generating method in an algebraic 
curve rrypto^aph v having the definition expression of aY^ + gX^ +1 -0 as claimed in Claim 
1 8, further comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element co by use of the equation co = Zt [<t/a> + <t^>] 6 _{-f ' } (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fractional portion X-[X] of the 
rational number X, 6t indicates Galois mapping in the ab cyclotomic (^ is the 

primitive ab root of 1)), based on the prime number a and the prime number b. 
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21 . (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptograph y having the definition expression of aY^ + 3X^ +1^0 as claimed in Claim 
18, further comprising: 

said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer y generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y"". 

22. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptograph y having the definition expression of aY'^ + 6X^ +1^0 as claimed in Claim 
18, further comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element co by use of the equation co = Zt [<t/a> + <t/b>] 6 _{-r* } (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fractional portion X-[k] of the 
rational number K 6t indicates Galois mapping ^ in the ab cyclotomic (^ is the 
primitive ab root of 1)), based on the prime number a and the prime number b; and 

said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer y generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y*^. 

23. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of aY'' + BX^ + 1 = Q as claimed in Claim 
18, further comprising: 
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said order candidate value computing procedure for computing a candidate value 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = Normjc/g (1+ (-Q*" j) (where Norm {K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}. 

24. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptograph v having the definition expression of aY'^ + BX^ -fl = 0 as claimed in Claim 
1 8, further comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element cd by use of the equation co = Zt [<t/a> + <t/b>] 6 _{-t'*} (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fractional portion X-[X] of the 
rational number X, 6t indicates Galois mapping i; in the ab cyclotomic (C, is the primitive 
ab root of 1)), based on the prime number a and the prime number b; and 

said order candidate value computing procedure for computing a candidate value hk 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormK/q (1+ (-Q^" j) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}. 

25. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of aY" + 6X^ +1 = 0 as claimed in Claim 
18, further comprising: 
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said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer 1 generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y^; and 

said order candidate value computing procedure for computing a candidate value h^ 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hu = NormK/g (1+ «f }) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}- 

26. (Currently Amended) A secure parameter generating method in an algebraic 
curve nryptograph v having the definition expression of aY^ + gX^ +1 = 0 as claimed in Claim 
18, further comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element co by use of the equation co = Zt [<t/a> + <tA»] 6 (where, t runs on a typical 

series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fractional portion X-[X] of the 
rational number X, 6t indicates Galois mapping C in the ab cyclotomic (<; is the primitive 
ab root of 1)), based on the prime number a and the prime number b; 

said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer y generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element 0), and computing the Jacobian addition 
candidate value j by use of the equation j = y"^; and 
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said order candidate value computing procedure for computing a candidate value hk 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = Normjc/Q (1+ (-Q^ j) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H^{hi,h2,... ,h2ab}. 

27. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of aY'^ + BX^ +1 = 0 as claimed in Claim 
18, fiirther comprising: 

said parameter deciding procedure for requiring the primitive a root and the 
primitive b root C,^ of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation C,a\ + C^h^ + 1=0, as for 
each integer 1 from 1 to a inclusively and each integer in from 1 to b inclusively, computing^; 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, C,^\ 
and C,h^ as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 

28. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of aY^ + 8X^ +1 - 0 as claimed in Claim 
18, further comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element co by use of the equation © = Zt [<t/a> + <t^>] 6 _{-f^} (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fractional portion X-[X] of the 
rational number X, 6t indicates Galois mapping (;->C^ in the ab cyclotomic (i; is the 
primitive ab root of 1)), based on the prime number a and the prime number b; and 
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said parameter deciding procedure for requiring the primitive a root and the 
primitive b root C,^ of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation C,a\ + X'' + 1=0, as for 
each integer 1 from 1 to a inclusively and each integer in from 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, 
and ^b*" as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 

29. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of aY^ + BX^ +1 = 0 as claimed in Claim 
18, fiirther comprising: 

said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer y generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element (o, and computing the Jacobian addition 
candidate value j by use of the equation j = y"; and 

said parameter deciding procedure for requiring the primitive a root Ca and the 
primitive b root of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation + C,b" + 1=0, as for 

each integer 1 from 1 to a inclusively and each integer in from 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, C,J, 
and (^b"" as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 
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30. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptograph y having the definition expression of aV^ + gX^ +1=0 as claimed in Claim 
18, further comprising: 

said order candidate value computing procedure for computing a candidate value hk 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormK/q (1+ (-Cf j) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer fi-om 1 to 2ab inclusively, when is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H-{hi,h2,... ,h2ab}; and 

said parameter deciding procedure for requiring the primitive a root and the 
primitive b root of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation C,J, + C,h^ + 1=0, as for 
each integer 1 fi-om 1 to a inclusively and each integer in fi-om 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, C,J, 
and ^b"" as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 

3 1 . (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition express ion of r^Y" + flX' +1 = 0 as claimed in Claim 
18, fiirther comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element co by use of the equation co = St [<t/a> + <t^>] 6 _{-r* } (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [k] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fi-actional portion X-[X] of the 
rational number X, 6t indicates Galois mapping in the ab cyclotomic (C, is the primitive 

ab root of 1)), based on the prime number a and the prime number b; 
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said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer y generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element cd, and computing the Jacobian addition 
candidate value j by use of the equation j = y*^; and 

said parameter deciding procedure for requiring the primitive a root C,^ and the 
primitive b root of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation C,^\ + i;^"' + 1=0, as for 
each integer 1 from 1 to a inclusively and each integer m from 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, C,a\ 
and (;b"' as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 

32. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of aY^ + BX^ +1 = 0 as claimed in Claim 
18, fiirther comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element co by use of the equation co = Zt [<t/a> + <t^>] 6 _{-f' } (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fractional portion X-[X] of the 
rational number X, 6t indicates Galois mapping i; ^ in the ab cyclotomic (<; is the primitive 
ab root of 1)), based on the prime number a and the prime number b; 

said order candidate value computing procedure for computing a candidate value hk 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormK/g (1+ (-Q*" j) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when is the 
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primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}; and 

said parameter deciding procedure for requiring the primitive a root and the 
primitive b root C,^ of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation + ^b"" X** + 1=0, as for 

each integer 1 from 1 to a inclusively and each integer in from 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, 
and i^b" as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 

33. (Currently Amended) A secure parameter generating method in an algebraic 
curve rryptnpraph v having the definition expression of aY° + gx" +1 = 0 as claimed in Claim 
18, ftirther comprising: 

said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer y generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element co, and computing the Jacobian addition 
candidate value j by use of the equation j = y"; 

said order candidate value computing procedure for computing a candidate value hk 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormK/Q (1+ i<f j) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when ^ is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}; and 
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said parameter deciding procedure for requiring the primitive a root and the 
primitive b root of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number Pi and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation C,J, + C,b" + 1=0, as for 
each integer 1 fi-om 1 to a inclusively and each integer in fi-om 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, C,^, 
and i^b"" as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 

34. (Currently Amended) A secure parameter generating method in an algebraic 
curve cryptography having the definition expression of a Y" + 3X^ +1 = 0 as claimed in Claim 
1 8, fiuiher comprising: 

said Stickelberger element computing procedure for computing the Stickelberger 
element (d by use of the equation o = Zt [<t/a> + <t/h>] 6 _{-f'} (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fi-actional portion of the 
rational number X, 6t indicates Galois mapping C ^ ^' in the ab cyclotomic (^ is the primitive 
ab root of 1)), based on the prime number a and the prime number b; 

said Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer 1 generating a prime ideal of a cyclotomic K generated 
by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime number a, the prime number b, the size n of the 
encryption key, and the Stickelberger element (o, and computing the Jacobian addition 
candidate value j by use of the equation j = y"; 

said order candidate value computing procedure for computing a candidate value hk 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = Normx/Q (1+ «f j) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer fi-om 1 to 2ab inclusively, when C, is the 
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primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}; and 

said parameter deciding procedure for requiring the primitive a root C^^ and the 
primitive b root C;^ of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation C^^, + i^b"^ + 1=0, as for 
each integer 1 firom 1 to a inclusively and each integer in from 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, C,^^, 
and C,\^ as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
with the candidate value h, of the algebraic curves specified by the prime number a and the 
prime number b if the result is equal to an identity element in the Jacobian group. 

35. (Currently Amended) A computer readable memory storing a program for 
generating a secure parameter in an algebraic curve cryptography having the definition 
expression of ofY^ + /3X^ +1=0 , to run the program on a computer, 

the program comprising the steps of: 

a Stickelberger element computing procedure for computing a Stickelberger element 
CD in an ab cyclotomic, respectively based on two different prime numbers a and b specifying 
degree of complexity of curve; 

a Jacobian addition candidate value computing procedure for computing Jacobian 
addition candidate value j corresponding to the two different prime numbers a and b, and a 
prime number p corresponding to the Jacobian addition candidate value j, respectively based 
on the prime number a, the prime number b, the size n of an encryption key, and the 
Stickelberger element co; 

an order candidate value computing procedure for computing a class H consisting of a 
plurality of candidate values for order of a Jacobian group of an algebraic curve specified by 
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the prime number a and the prime number b, respectively based on the prime number a, the 
prime number b, and the Jacobian addition candidate value j; 

a security judging procedure for searching for a candidate value h meeting a security 
condition such as almost prime number characteristic from the class H, according to the class 
H; and 

a parameter deciding procedure for computing a parameter of an algebraic curve 
whose order of the Jacobian group is in accord with the candidate value h, of the algebraic 
curves specified by the prime number a, the prime number b, and the prime number p, 
respectively based on the prime number a, the prime number b, the prime number p, and the 
candidate value h. 

36. (Currently Amended) A computer readable memory storing a program for 
generating a secure parameter in an algebraic curve cryptography having the definition 
expression of c^Y' + 3X^ +1=0 , 

the program comprising the steps of: 

a_said-Stickelberger element computing procedure for computing the Stickelberger 
element co by use of the equation co = Zt [<t/a> + <t/b>] 6 _{-t'^} (where, t runs on a typical 
series of irreducible residue class with ab used as a divisor, [X] indicates the maximum 
integer not exceeding a rational number X, <X> indicates a fractional portion X'[X] of the 
rational number X, 6t indicates Galois mapping C ^ in the ab cyclotomic (C, is the primitive 
ab root of 1)), based on the prime number a and the prime number b. 

37. (Currently Amended) A computer readable memory storing a program for 
generating a secure parameter in an algebraic curve cryptography having the definition 
expression of aY^ + BX^ +1 - 0 , 

the program comprising the steps of: 

a_said-Jacobian addition candidate value computing procedure for generating a at 
random, which is an algebraic integer y generating a prime ideal of a cyclotomic K generated 
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by the primitive ab root of 1 and whose absolute norm becomes the prime number p of bit 
length 2n/(a-l)(b-l) or so, based on the prime nvunber a, the prime number b, the size n of the 
encryption key, and the Stickelberger element o), and computing the Jacobian addition 
candidate value j by use of the equation j = y*^; 

38. (Currently Amended) A computer readable memory storing a program for 
generating a secure parameter in an algebraic curve cryptography having the definition 
expression of aY^ + j8X^ +1 = 0 , 

the program comprising the steps of: 

an said-order candidate value computing procedure for computing a candidate value hk 
for the order of the Jacobian group of an algebraic curve specified by the parameters a and b, 
using the equation hk = NormK/Q (1+ «t j) (where Norm_{K|Q} is a norm mapping in the ab 
cyclotomic K), as for each k that is an integer from 1 to 2ab inclusively, when C, is the 
primitive ab root of 1, based on the prime number a, the prime number b, and the Jacobian 
addition candidate value j, and computing the class of the candidate values, 
H={hi,h2,... ,h2ab}- 

39. (Currently Amended) A computer readable memory storing a program for 
generating a secure parameter in an algebraic curve cryptograph y having the definition 
expression of Q!Y^ + BX^ +1 = 0, 

the program comprising the steps of: 

a_said-parameter deciding procedure for requiring he primitive a root C,a^ and the 
primitive b root C^h of 1 with the prime number p used as the divisor, based on the prime 
number a, the prime number b, the prime number p, and the candidate value h, generating a 
random point G over an algebraic curve defined by the equation C^J, + ^b"" X*' + 1=0, as for 
each integer 1 from 1 to a inclusively and each integer in from 1 to b inclusively, computing 
the h-fold of an element in the Jacobian group indicated by the point G, and supplying p, C.J, 
and C^yT as the parameter of an algebraic curve whose order of the Jacobian group is in accord 
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prime number b if the result is equal to an identity element in the Jacobian group. 
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